Live data from Hacker News

Anonymous Hacks Epik

4chan.partyvan.epikfail.win

261–270 of 284 posts

Re: Anonymous Hacks Epik

#261
post #149

Earlier quoted context omitted.

Nice catch! I downvoted though, because helping to deanonymize antifascist hackers is against my ethics.

The ethical thing to do when you find a security breach is to report it to them. If you support people who are willing to commit crime to get into power then I really hope that you take some time to think about your political convictions.

> The ethical thing to do when you find a security breach is to report it to them.

Do you hold secret services and private hacking companies (Hacking Team, Cellebrite..) to the same standards? If not, why are you complaining about this instance of small-scale hacking for the lulz, and not about the actual insecurity industry who derives power/authority and money from hacking?

> If you support people who are willing to commit crime to get into power

I certainly don't. I despise power in all forms, unless you're talking power as in "empowerment" or "power to the people". I will however, defend and help anyone committing crimes to abolish power and injustice, because "justice" is not something that can be measured or achieved with the oppressors's tools, namely laws and repression.

If you don't support people who break unjust laws and help make those abusing power accountable, I really hope that you take some time to think about your political convictions, and what you would have thought of the Resistance movement against nazi occupation during WWII.

Re: Anonymous Hacks Epik

#262

Earlier quoted context omitted.

Nice catch! I downvoted though, because helping to deanonymize antifascist hackers is against my ethics.

So you are saying that this Epik company was run by fascists?

I'm saying they are very confident and happy to host actual fascists and other stripes of neo-nazis and white supremacists. I have no clue about their own personal opinions, although some people further down this thread suggested they had such affiliations.

Providing material support to people is never neutral. I'm happy some sysadmins and community managers are taking a stand against abuse and harassment. On the other hand i'm also concerned State-mandated censorship is detrimental to human rights and will in fact be used more (as it already is) against anarchists, queers and other minorities and not against actual fascists because our governments are much closer to the historical definitions of "fascism" than they'd like to admit. So i'm clearly against censorship, but i agree with XKCD that kicking assholes out of our communities is not a "free speech" issue: https://xkcd.com/1357/

I can't say i'm very comfortable with these "free speech" hosts who would certainly turn away any opinions they disagree with. I much prefer radical servers like riseup/autistici who have clear policies on where they stand politically and what kind of activities they're ready to fight for and what kind of activities they'll fight off.

Contrary to Protonmail and their millions of dollars, Riseup is a self-organized non-profit (born of the altermondialist/internationalist movement) who had servers seized rather than rat on their users [0]... unless some people/activities directly contradict their ethical principles in which case they reserve the right to collaborate with law enforcement [1] instead of risking the infrastructure needed by all their users (as in a seppuku pledge, like Lavabit did).

[0] https://riseup.net/en/about-us/press/fbi-seizes-anonymous-re... [1] https://riseup.net/en/about-us/policy/government-faq#what-ab...

Re: Anonymous Hacks Epik

#263
post #27
post #14

Earlier quoted context omitted.

How many just regular folks would actually pick Epik? Why?

I intend to for future domain registration. - Register.com is an annoying cesspool of value-add upsells and is extremely expensive in the process, with added cost to not have your personal info attached directly to your domain whois. - GoDaddy, other than the creepy ads, has shown plenty of willingness to remove domains hosting content that they don't like, even if it's legal. - I think Google is a registrar, but I'm…

Ideology aside, shouldn't the fact that this hack exposed gigabytes of user data cause you to reconsider them as a reliable domain provider?

Why be concerned with domain providers giving personal information to authorities when Epik has already given it to the entire internet?

Re: Anonymous Hacks Epik

#264

Earlier quoted context omitted.

I dont remember and I have no idea what you are alluding to You can literally generate any public key / address hash that conforms with a blockchain and sign it and anyone can verify that you therefore control it This has zero crypto assets involved and has no trail of assets so what are you talking about? If anyone sends funds to the address hash the owners can just tornado.cash it and withdraw it somewhere else wit…

> They should sign an ethereum address to reduce ambiguity ^I'm responding to this _If_. I am still openly questioning the nature of blockchain and open ledgers: trivial associations with transaction activity and address history can be had or via more complex analysis with clustering, modeling, etc (ie: Chainalysis). I used to think that a simple signature confirmation claiming "this is my email address" would be oka…

Yes, you are confusing and conflating a lot of topics simply because you saw the word Ethereum or blockchain (or maybe "signature" if I'm reading this correctly). A lot of people do it. I've been in plenty of circumstances where people go on incoherent jumbles of words in response to the word blockchain.

Signing an address has nothing to do with linkability or transaction history, or even blockchains, as this is not a transaction and requires no funds. It requires having generated the private key, client side. Signing proves you control the private key, public key and address hash. A signature allows other people to verify that you in fact do have control of that address. When looking at the address on a blockchain, it can be empty, no funds, and simply relegated to being a unique identifier for the person that signed the address.

Okay, so let's assume this is confusing because it conflicts with something else you thought you experienced regarding blockchains. Well just erase all that from your mind, and read on:

Blockchains use a namespace of address hashes. Private keys to generate those address hashes are only generated client side by the user, and there is enough randomness and entropy for no other user to generate the same private key, public key and address hash. But within the namespace, all public keys and address hashes already exist. I think this is the fundamentally different paradigm than account numbers like at a bank. At banks, for example, accounts numbers are incremental. ie. When an account is created new row is added to the account database it has an ID that goes up by one, and all the attributes of the account did not exist until the point in time that the server was instructed to create the account. In blockchains using a designated cryptographic namespace, all accounts therefore already exist and access must be generated client side by the user. The namespace is extremely large, which allows for assurances that nobody generates the same private keys, public keys and address hash. The other countintuitive thing to understand is that these accounts don't exist "on" the blockchain until someone sends funds to them. An empty address means it has never been seen on the blockchain, as this record only occurs after a digital asset or message references them in a prior transaction. GUI's for browsing blockchains smooth this over by letting you look at empty addresses simply by nature of them complying with the namespace, but an address that has never previously received funds or any other message is not in the blockchain at all, yet. The reason this is important is because if you have the private key to that address, you can still convey that you have control of that address via signing and there is no prior link to any other address or funds. There is no linkability or privacy issue. Signing just lets you have a unique identifier.

Using all that, to go back to what I said earlier, cryptocurrency wallets just makes public and private key cryptography so prevalent that signing is also more prevalent and available. Whereas PGP and GPG Suites had 25 years to do so and have not been successful outside of much much much smaller niches, that have not seem to have grown at all and the user experience arguably has gotten worse.

What you mentioned about NFT art signatures is a different topic. Address signing is about offchain signatures. All transactions and onchain metadata are onchain signatures.

Re: Anonymous Hacks Epik

#265
post #199

Earlier quoted context omitted.

Sure, this dude sound like nuts from comments describing him here (I can’t even be bothered to look this shit up myself) and I’m glad I dodged a bullet. However, the private info of all their customers from their inception are allegedly exposed; and lots of people here seem to be cheering the hackers on. Does this mean we need — actually, needed — to do research on the political standings of every founder, CEO, CXO o…

> These hackers are just criminals illegally doxxing a huge number of people. They don’t deserve cheers. Fully agree. First and foremost the rule of law must be blind. However, spectators need not be similarly blind. I am not cheering on the hackers. I am merely accepting the Newtonian forces at work here. I doubt that there are many (any?) Epik customers who I would consider good people (there’s simply no logical re…

> I doubt that there are many (any?) Epik customers who I would consider good people (there’s simply no logical reason to host with them otherwise)

This is an incredibly shortsighted / insular perspective. We live in a world where conservative orthodox Jews (e.g. Ben Shapiro) are called Nazi's and conservative Black folks (Larry Elder) are being called white supremacists, simply for being conservative. Likewise, progressives and other left leaning individuals that dare utter criticism of the left are met with the milder insult of being called conservative (e.g. Tim Pool, Glenn Greenwald, Bill Maher). People are deliberately shifting the overton window to a ridiculous degree and the scary thing is that they are getting away with it.

I can imagine a lot of regular conservatives worry about censorship and may find Epik to be a safer bet than, say, Google who blocks pro-life ads [1]. I can understand that maybe from your perspective (assuming you're left leaning) you are not aware of how hostile society has become to mainstream conservatism, but you should try to see things from the perspective of a regular conservative who sees prominent mainstream conservatives being slandered, lied about, and cancelled all around them.

Aside from that, Epik did have a few differentiating features like offering single purchase lifetime Domain ownership that I haven't seen elsewhere, which by itself could be sufficient motivation for people to host with them, without the necessarily knowing anything about potential controversy surrounding the business.

[1] https://www.nationalreview.com/corner/google-blocks-ad-for-s...

Re: Anonymous Hacks Epik

#266

Earlier quoted context omitted.

Remember when a guy murdered 11 people in a Pittsburgh synagogue? When it was revealed the shooter had posted about it on Gab beforehand, every service powering the social network pulled the plug. Epik was who brought them back online.[0] The hero of hate speech is not exactly a sterling reputation to have. [0] https://www.wired.com/story/how-right-wing-social-media-site...

So you believe that Facebook should be shut down because the Christchurch shooter livestreamed his crime there?

Sigh. Facebook would not be a willing participant in this situation.

Re: Anonymous Hacks Epik

#267

Earlier quoted context omitted.

> nowadays it is much more likely that you will see such content while browsing facebook. That sounds... unlikely? Unless you have a very specific set of friends?

I don't have a facebook account so no.

then why did you say

> while nowadays it is much more likely that you will see such content while browsing facebook.

Re: Anonymous Hacks Epik

#268
post #53

Earlier quoted context omitted.

Google Domains incorrectly banned me. I filed an appeal showing how I was indeed authorized to perform the actions I had performed, that I was not in violation of their Terms of Use, and included the contact information of the various parties that Google could contact in order to confirm my claims. None of these individuals were contacted and my appeal was rejected with their standard "unfortunately kindly go fuck yo…

Without reading the registry agreement to find anything specific, I'm pretty sure that violates ICANN rules. I would also like to hear more about it because that's scary.

I posted the story on a sibling comment. It's not as exciting as all that.

Overall it was a net positive experience, really. It led me to perform a personal Disaster Recovery exercise where I modeled losing my Google account, which was very interesting and informed a significant shift in my online behavior. If it ever happens, it'll be a bother, but not much more than that.

Re: Anonymous Hacks Epik

#269

Earlier quoted context omitted.

> They should sign an ethereum address to reduce ambiguity ^I'm responding to this _If_. I am still openly questioning the nature of blockchain and open ledgers: trivial associations with transaction activity and address history can be had or via more complex analysis with clustering, modeling, etc (ie: Chainalysis). I used to think that a simple signature confirmation claiming "this is my email address" would be oka…

Yes, you are confusing and conflating a lot of topics simply because you saw the word Ethereum or blockchain (or maybe "signature" if I'm reading this correctly). A lot of people do it. I've been in plenty of circumstances where people go on incoherent jumbles of words in response to the word blockchain. Signing an address has nothing to do with linkability or transaction history, or even blockchains, as this is not…

So how would an "anonymous group" benefit from signing an "ethereum address to reduce ambiguity"? Ambiguity from what context?

Re: Anonymous Hacks Epik

#270

Earlier quoted context omitted.

This is what I was told by an attorney. That in (the attorney) doing an asset check they revealed that NameCheap simply has a virtual office in a Regus office space with little to no US assets. Further, that even if we went through the struggle of getting a judgement against NameCheap's US entity that getting cash out might be impossible. If anyone reading this wants to verify you can look at Namecheap's site where t…

Take note. Calling someone's experience "incorrect" and "absurd" before you have all the details will never end well.

I was simply saying it is incorrect to say that we are not a US-based company. We have a large support team in Europe but we were founded in the US and remain a US entity. We have always been a distributed company with remote teams all around the world. It is indeed absurd that their attorney suggested that they would have to through the "Ukraine court system."
Post reply on HN